AWS Certified Developer – Associate (DVA-C02)DeploymentMedium

A developer needs to deploy an AWS Lambda function that processes sensitive customer data. To meet compliance requirements, the Lambda function must only be able to access specific Amazon S3 buckets and a particular Amazon DynamoDB table. Additionally, the function should not have public internet access. How should the developer configure the Lambda function and its permissions?

  1. ADeploy the Lambda function inside a VPC, configure VPC endpoints for S3 and DynamoDB, and attach an IAM policy with least privilege access to the specific resources.
  2. BDeploy the Lambda function inside a VPC, configure a NAT Gateway for S3 and DynamoDB access, and attach an IAM policy with least privilege access.
  3. CAttach an IAM policy to the Lambda function's execution role with full S3 and DynamoDB access, and ensure no security groups are attached to the function.
  4. DAttach an IAM policy to the Lambda function's execution role allowing access to all S3 buckets and DynamoDB, and configure a NAT Gateway for internet access.
Show answer & explanation

Correct answer: A. Deploy the Lambda function inside a VPC, configure VPC endpoints for S3 and DynamoDB, and attach an IAM policy with least privilege access to the specific resources.

To restrict network access and enforce least privilege, the Lambda function should be deployed within a VPC. To allow access to S3 and DynamoDB without traversing the public internet, VPC endpoints (Gateway Endpoint for S3, Interface Endpoint for DynamoDB) are necessary. Finally, an IAM policy must be attached to the Lambda's execution role, granting only the required permissions to the specific S3 buckets and DynamoDB table.

Why the other options are wrong

  • B. Using a NAT Gateway provides public internet access, which is explicitly disallowed. VPC endpoints are the correct way to access S3/DynamoDB privately from a VPC without internet access.
  • C. Full S3 and DynamoDB access violates least privilege. Not attaching security groups would mean default behavior, which might not be restrictive enough, and it doesn't address the private network access requirement.
  • D. Allowing access to 'all S3 buckets and DynamoDB' violates least privilege. NAT Gateway provides internet access, which is explicitly not desired for sensitive data processing.

Lambda VPC & Endpoints

Deploying a Lambda function in a VPC provides network isolation. VPC endpoints allow private and secure access to AWS services like S3 and DynamoDB from within the VPC without routing through the public internet.

  • Lambda in VPC isolates network traffic.
  • VPC endpoints provide private access to AWS services.
  • Gateway Endpoint for S3, Interface Endpoint for DynamoDB.
  • Combined with IAM for least privilege access control.

Memory trick: VPC and endpoints, for private data friends.

More Deployment questions